<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>policy-management</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/1002/feed"/>
    <updated>2026-08-09T00:23:41+00:00</updated>
    <id>https://links.biapy.com/guest/tags/1002/feed</id>
            <entry>
            <id>https://links.biapy.com/links/12819</id>
            <title type="text"><![CDATA[Capsule]]></title>
            <link rel="alternate" href="https://projectcapsule.dev/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12819"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A multi-tenancy and policy-based framework for Kubernetes.

Capsule implements a multi-tenant and policy-based environment in your Kubernetes cluster. It is designed as a micro-services-based ecosystem with the minimalist approach, leveraging only on upstream Kubernetes.

- [Capsule @ GitHub](https://github.com/projectcapsule/capsule).]]>
            </summary>
            <updated>2026-05-22T16:17:38+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12480</id>
            <title type="text"><![CDATA[Agent Governance Toolkit]]></title>
            <link rel="alternate" href="https://github.com/microsoft/agent-governance-toolkit" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12480"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10. 

Runtime governance for AI agents — the only toolkit covering all 10 OWASP Agentic risks with 9,500+ tests. Governs what agents do, not just what they say — deterministic policy enforcement, zero-trust identity, execution sandboxing, and SRE — Python · TypeScript · .NET · Rust · Go

Related contents:

- [Introducing the Agent Governance Toolkit: Open-source runtime security for AI agents @ Microsoft Open Source Blog](https://opensource.microsoft.com/blog/2026/04/02/introducing-the-agent-governance-toolkit-open-source-runtime-security-for-ai-agents/).
- [Microsoft&amp;#039;s Newest Open-Source Project: Runtime Security For AI Agents @ Phoronix](https://www.phoronix.com/news/Microsoft-AI-Agent-Governance).
- [Episode 661: Sink Your Claws In @ Linux Unplugged](https://linuxunplugged.com/661).]]>
            </summary>
            <updated>2026-04-09T06:18:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12356</id>
            <title type="text"><![CDATA[Heddle]]></title>
            <link rel="alternate" href="https://github.com/goweft/heddle" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12356"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The policy-and-trust layer for MCP tool servers. Turn YAML configs into validated, policy-enforced MCP tools. 

 Heddle turns declarative configs into Model Context Protocol servers
with trust enforcement, credential brokering, and tamper-evident audit logging built in.]]>
            </summary>
            <updated>2026-03-29T15:26:41+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10272</id>
            <title type="text"><![CDATA[Policy Reporter]]></title>
            <link rel="alternate" href="https://kyverno.github.io/policy-reporter-docs/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10272"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Unified Policy Observability.
 Monitoring and Observability Tool for the PolicyReport CRD with an optional UI. 

Policy Reporter was created to make the results of your Kyverno validation policies more visible and observable. By default, Kyverno provides the option to create your validation policies in audit or enforce mode. While enforce blocks to applying a manifests that violate the given policy, audit creates PolicyReports that provide information about all resources that pass or fail your policies. Because Policy Reports are simple Custom Resource Definitions you can access them with kubectl get/describe.

- [Policy Reporter @ GitHub](https://github.com/kyverno/policy-reporter).
-[Policy Reporter UI @ GitHub](https://github.com/kyverno/policy-reporter-ui).]]>
            </summary>
            <updated>2025-09-18T13:07:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1097</id>
            <title type="text"><![CDATA[Cedar Language]]></title>
            <link rel="alternate" href="https://www.cedarpolicy.com/en" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1097"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Cedar is a language for defining permissions as policies, and a specification for evaluating those policies. Use Cedar to define who is authorized to do what within your application. Cedar is open source.

- [Cedar @ GitHub](https://github.com/cedar-policy/cedar).

Related contents:

- [Cedar: A New Approach to Policy Management for Kubernetes @ Cloud Native computing foundation](https://www.cncf.io/blog/2025/03/28/cedar-a-new-approach-to-policy-management-for-kubernetes/).
- [Cedar Joins CNCF as a Sandbox Project @ InfoQ](https://www.infoq.com/news/2026/01/cedar-joins-cncf-sandbox/).]]>
            </summary>
            <updated>2026-02-04T12:55:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2870</id>
            <title type="text"><![CDATA[Policy Sentry]]></title>
            <link rel="alternate" href="https://policy-sentry.readthedocs.io/en/latest/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2870"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[IAM Least Privilege Policy Generator.

Policy Sentry is an AWS IAM Least Privilege Policy Generator, auditor, and analysis database. It compiles database tables based on the AWS IAM Documentation on Actions, Resources, and Condition Keys and leverages that data to create least-privilege IAM policies.

- [Policy Sentry @ GitHub](https://github.com/salesforce/policy_sentry).]]>
            </summary>
            <updated>2025-08-28T23:54:32+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3709</id>
            <title type="text"><![CDATA[Open Policy Agent]]></title>
            <link rel="alternate" href="https://www.openpolicyagent.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3709"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Policy-based control for cloud native environments.
Flexible, fine-grained control for administrators across the stack.

Open Policy Agent (OPA) is an open source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack.

- [Open Policy Agent @ GitHub](https://github.com/open-policy-agent/opa).

Related contents:

- [Guardrails for Your Cloud: A Simple Guide to OPA and Terraform @ Sami Banerjee&amp;#039;s Medium](https://medium.com/@er.samibanerjee/guardrails-for-your-cloud-a-simple-guide-to-opa-and-terraform-aada0d589dc5).
- [Getting Open Policy Agent Up and Running @ The New Stack](https://thenewstack.io/getting-open-policy-agent-up-and-running/). 
- [Simplify Kubernetes Security With Kyverno and OPA Gatekeeper @ The New Stack](https://thenewstack.io/simplify-kubernetes-security-with-kyverno-and-opa-gatekeeper/).
- [Automating policy enforcements for infrastructure using Open Policy Agent (OPA) in Terraform — Part 1 @ Ashay Maheshwari&amp;#039;s Medium](https://aashay-arya.medium.com/automating-policy-enforcements-for-infrastructure-using-open-policy-agent-opa-in-terraform-a78a78bb34a1).
- [Terraform governing with OPA @ DevOpsOnTheTrail](https://devopsonthetrail.com/terraform-governing-with-opa/).
- [Blueprinting Security in CI/CD: Building Trust Through Open Source @ CD Foundation](https://cd.foundation/blog/2026/02/06/blueprinting-security/).
- [From Kubernetes Gatekeeper to Full-Stack Governance with OPA @ Pulumi](https://www.pulumi.com/blog/kubernetes-gatekeeper-full-stack-governance-opa/).
- [Governing infrastructure as code using pattern-based policy as code @ AWS Security Blog](https://aws.amazon.com/blogs/security/governing-infrastructure-as-code-using-pattern-based-policy-as-code/).]]>
            </summary>
            <updated>2026-06-02T06:54:19+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4725</id>
            <title type="text"><![CDATA[Kyverno]]></title>
            <link rel="alternate" href="https://kyverno.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4725"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Kubernetes Native Policy Management.

Kyverno is a policy engine designed for Kubernetes.
It can validate, mutate, and generate configurations using admission controls and background scans.
Kyverno policies are Kubernetes resources and do not require learning a new language.
Kyverno is designed to work nicely with tools you already use like kubectl, kustomize, and Git. 

- [Kyverno @ GitHub](https://github.com/kyverno/kyverno/).

Related contents:

- [Vos politiques de conformité sur Kubernetes avec Kyverno @ Zwindler&amp;#039;s Reflection :fr:](https://blog.zwindler.fr/2022/08/01/vos-politiques-de-conformite-sur-kubernetes-avec-kyverno/).
- [Understanding Kyverno: Enhancing Kubernetes Security with Policy Enforcement @ Jyothi Ram&amp;#039;s blog](https://jyothiram.hashnode.dev/understanding-kyverno-enhancing-kubernetes-security-with-policy-enforcement).
- [Using the Kyverno CLI to Write Policy Test Cases @ The New Stack](https://thenewstack.io/using-the-kyverno-cli-to-write-policy-test-cases/).
- [Simplify Kubernetes Security With Kyverno and OPA Gatekeeper @ The New Stack](https://thenewstack.io/simplify-kubernetes-security-with-kyverno-and-opa-gatekeeper/).
- [Announcing Kyverno Release 1.15! @ CNCF](https://www.cncf.io/blog/2025/08/30/announcing-kyverno-release-1-15/).
- [Optimizing Kyverno CLI performance: My LFX mentorship journey @ CNCF](https://www.cncf.io/blog/2025/12/10/optimizing-kyverno-cli-performance-my-lfx-mentorship-journey/).
- [GitOps architecture, patterns and anti-patterns @ Platform Engineering](https://platformengineering.org/blog/gitops-architecture-patterns-and-anti-patterns).
- [GitOps policy-as-code: Securing Kubernetes with Argo CD and Kyverno @ CNCF](https://www.cncf.io/blog/2026/04/02/gitops-policy-as-code-securing-kubernetes-with-argo-cd-and-kyverno/).
- [Automating Confidential Containers (CoCo) infrastructure with Kyverno @ CNCF](https://www.cncf.io/blog/2026/05/19/automating-confidential-containers-coco-infrastructure-with-kyverno/).]]>
            </summary>
            <updated>2026-05-20T11:47:50+00:00</updated>
        </entry>
    </feed>
